Search CVE reports


Toggle filters

171 – 180 of 48426 results

Status is adjusted based on your filters.


CVE-2026-35536

Medium priority
Needs evaluation

In Tornado before 6.5.5, cookie attribute injection could occur because the domain, path, and samesite arguments to .RequestHandler.set_cookie were not checked for crafted characters.

1 affected package

python-tornado

Package 16.04 LTS
python-tornado Needs evaluation
Show less packages

CVE-2026-35535

High priority
Not affected

In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation.

1 affected package

sudo

Package 16.04 LTS
sudo Not affected
Show less packages

CVE-2026-27456

Medium priority
Needs evaluation

util-linux is a random collection of Linux utilities. Prior to version 2.41.4, a TOCTOU (Time-of-Check-Time-of-Use) vulnerability has been identified in the SUID binary /usr/bin/mount from util-linux. The mount binary, when...

1 affected package

util-linux

Package 16.04 LTS
util-linux Needs evaluation
Show less packages

CVE-2026-35414

Medium priority
Needs evaluation

OpenSSH before 10.3 mishandles the authorized_keys principals option in uncommon scenarios involving a principals list in conjunction with a Certificate Authority that makes certain use of comma characters.

2 affected packages

openssh, openssh-ssh1

Package 16.04 LTS
openssh Needs evaluation
openssh-ssh1
Show less packages

CVE-2026-34835

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Request parses the Host header using an AUTHORITY regular expression that accepts characters not permitted...

1 affected package

ruby-rack

Package 16.04 LTS
ruby-rack Needs evaluation
Show less packages

CVE-2026-34827

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21, and 3.2.0 to before 3.2.6, Rack::Multipart::Parser#handle_mime_head parses quoted multipart parameters such as Content-Disposition:...

1 affected package

ruby-rack

Package 16.04 LTS
ruby-rack Needs evaluation
Show less packages

CVE-2026-32762

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. From versions 3.0.0.beta1 to before 3.1.21 and 3.2.0 to before 3.2.6, Rack::Utils.forwarded_values parses the RFC 7239 Forwarded header by splitting on semicolons before handling...

1 affected package

ruby-rack

Package 16.04 LTS
ruby-rack Needs evaluation
Show less packages

CVE-2026-26962

Medium priority
Needs evaluation

Rack is a modular Ruby web server interface. From version 3.2.0 to before version 3.2.6, Rack::Multipart::Parser unfolds folded multipart part headers incorrectly. When a multipart header contains an obs-fold sequence, Rack...

1 affected package

ruby-rack

Package 16.04 LTS
ruby-rack Needs evaluation
Show less packages

CVE-2026-35388

Medium priority
Needs evaluation

OpenSSH before 10.3 omits connection multiplexing confirmation for proxy-mode multiplexing sessions.

2 affected packages

openssh, openssh-ssh1

Package 16.04 LTS
openssh Needs evaluation
openssh-ssh1
Show less packages

CVE-2026-35387

Medium priority
Needs evaluation

OpenSSH before 10.3 can use unintended ECDSA algorithms. Listing of any ECDSA algorithm in PubkeyAcceptedAlgorithms or HostbasedAcceptedAlgorithms is misinterpreted to mean all ECDSA algorithms.

2 affected packages

openssh, openssh-ssh1

Package 16.04 LTS
openssh Needs evaluation
openssh-ssh1
Show less packages